McAfee Database Security 6Ô¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-06-07

0x00 Îó²î¸ÅÊö

McAfee Êý¾Ý¿âÇå¾²²úÆ·Äܹ»ÊµÊ±±£»£»£»¤Òªº¦ÓªÒµµÄÊý¾Ý¿â£¬£¬£¬£¬£¬×èÖ¹ÆäÔâÊÜÍⲿ¡¢ÄÚ²¿ºÍÊý¾Ý¿âÄÚ²¿µÄÖÖÖÖ¹¥»÷¡£¡£¡£¡£

2021Äê06ÔÂ01ÈÕ£¬£¬£¬£¬£¬McAfeeÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËDatabase SecurityÖеÄ5¸öÇå¾²Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓÃÕâЩÎó²îδÊÚȨ»á¼û¡¢»ñÈ¡Ãô¸ÐÐÅÏ¢»ò¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

±¾´ÎÐÞ¸´µÄ5¸öÎó²îÖУ¬£¬£¬£¬£¬CVE-2021-23894ºÍCVE-2021-23895ÊÇMcAfee Database Security £¨DBSec£©Öеķ´ÐòÁл¯Îó²î£¬£¬£¬£¬£¬Î´¾­ÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ý·¢ËͶñÒâ¹¹½¨µÄJavaÐòÁл¯¹¤¾ßµ½DBSecЧÀÍÆ÷À´´¥·¢´ËÎó²î£¬£¬£¬£¬£¬²¢Í¨¹ýÔÚDBSecЧÀÍÆ÷ÉϽ¨Éè¾ßÓÐÖÎÀíԱȨÏ޵ķ´ÏòshellÀ´¿ØÖÆÐ§ÀÍÆ÷¡£¡£¡£¡£

CVE-2021-31830ÊÇDBSecÖеÄXSSÎó²î£¬£¬£¬£¬£¬ÓµÓÐÖÎÀíȨÏ޵Ĺ¥»÷Õß¿ÉÒÔͨ¹ýÔÚÉèÖÃÒª¼à¿ØµÄÊý¾Ý¿âÃû³ÆÊ±Ç¶ÈëJavaScript´úÂ룬£¬£¬£¬£¬µ±ÈκÎÊÚȨÓû§µÇ¼µ½DBSec½çÃæ²¢·­¿ª¸ÃÊý¾Ý¿âµÄÊôÐÔÉèÖÃÒ³ÃæÊ±£¬£¬£¬£¬£¬½«´¥·¢¶ñÒâ´úÂ룬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥¡£¡£¡£¡£

CVE-2021-31831ÊÇDBSecÖÐÒÑɾ³ý¾ç±¾µÄ²»×¼È·»á¼ûÎó²î£¬£¬£¬£¬£¬ÕâЩ¾ç±¾±»±£´æÏÂÀ´£¬£¬£¬£¬£¬ÒÔ±ãÔÚδÀ´ÐèÒªÆÊÎöÍùÊÂÎñʱʹÓᣡ£¡£¡£µ«¾­ÓÉÈÏÖ¤µÄÔ¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýREST API»ñµÃ¶ÔÖÎÀí¿ØÖÆÌ¨ÖÐÒѱê¼ÇΪɾ³ý»òÓâÆÚµÄÊðÃûSQL¾ç±¾µÄ»á¼û£¬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥¡£¡£¡£¡£

CVE-2021-23896ÊÇDBSecÖÎÀíÔ±½çÃæÖеÄÃô¸ÐÐÅÏ¢Ã÷ÎÄ´«ÊäÎó²î£¬£¬£¬£¬£¬ÓµÓÐÖÎÀíȨÏ޵Ĺ¥»÷Õß¿ÉÒÔʹÓôËÎó²îÉó²éMcAfee Insights ServerµÄδ¼ÓÃÜÃÜÂ룬£¬£¬£¬£¬µ«Ê¹ÓôËÎó²îÐèÒªÓû§½»»¥¡£¡£¡£¡£

 

CVE-ID

ÀàÐÍ

CVSSv3ÆÀ·Ö

Ó°Ïì¹æÄ£

CVE-2021-23894

·´ÐòÁл¯

9.6

<   4.8.2

CVE-2021-23895

·´ÐòÁл¯

9.0

CVE-2021-23896

ÐÅϢй¶

3.2

CVE-2021-31830

XSS

5.9

CVE-2021-31831

»á¼û¿ØÖƹýʧ

4.9

 

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚMcAfeeÒѾ­ÔÚDBSec 4.8.2ÖÐÐÞ¸´ÁËÕâЩÎó²î£¬£¬£¬£¬£¬½¨ÒéʵʱÉý¼¶¸üУº

ÏÂÔØÅþÁ¬£º

https://www.mcafee.com/enterprise/en-us/downloads.html

 

0x03 ²Î¿¼Á´½Ó

https://kc.mcafee.com/corporate/index?page=content&id=SB10359#Remediation

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23894

https://nvd.nist.gov/vuln/detail/CVE-2021-23894

 

0x04 ʱ¼äÏß

2021-06-01  McAfeeÐû²¼Ç徲ͨ¸æ

2021-06-02  McAfee¸üÐÂÇ徲ͨ¸æ

2021-06-07  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png